Skip to main content

How to configure SSO with Google Workspace

To set up your Qase account with SSO/SAML and Google Workspace, you'll need to take the following steps:

  • Sign in to the Admin Console of your Google Workspace account. You’ll need to be a G Suite account administrator

  • Click through the “Apps - Manage apps and their settings” icon

    The Google Admin console home with the Apps tile, Manage apps and their settings, highlighted

  • Click on “SAML Apps”

    The Apps page in Google Admin with the SAML apps card highlighted

  • Click on the yellow plus button on the bottom right to add a new app

    The empty SAML Apps list with the yellow plus button highlighted in the bottom right corner

  • In “Step 1”, click on “Setup my own custom app” on the bottom:

    Step 1 of the Enable SSO for SAML Application dialog, with Setup my own custom app at the bottom

  • Copy the SSO URL, EntityID and download the Certificate. We will use them on the next steps. Click on the “Next button”.

    Step 2, Google IdP Information, showing the SSO URL, Entity ID and the certificate Download button

  • Fill the form with the application name and description. We suggest using “Qase” as the name of the app - it will be easier to find it in the future. Also, you can upload a logo. After the form is complete, click on the “Next” button.

    Step 3, Basic information for your Custom App, with the name Qase, a description and an uploaded logo

After you fill the form with necessary data, click on the “Next” button.

Step 4, Service Provider Details, filled with the Qase ACS URL, Entity ID, Start URL and EMAIL Name ID format
  • If you want to save the user's first name, last name, and job title in Qase, you need to add attribute mapping fields. That can be done by clicking on the “Add new mapping” button and selecting the values like on this screenshot:

    Step 5, Attribute Mapping, with fname, lname and title mapped to First Name, Last Name and Job Title

  • Google setup is complete. Now you need to go to the Qase security page and link your account with Google’s credentials. Click on the “Enable SSO/SAML” toggle button and fill the form:

  • SAML Sign-in URL: paste SSO URL from step 6.

  • Identity Provider Issuer: paste EntityID from step 6.

  • Key x509 Certificate: open downloaded in step 6 certificate in any editor, copy its content, and paste in the text area.

  • Domains*: provide a list of domains separated by a comma, that will be used for SSO. Public domains like Gmail, Hotmail, etc. are not allowed. *This step is mandatory.

Any domains that are added will need to be verified. To do so, you will need to add a TXT record to the domain's DNS records.

Adding the Qase domain verification TXT record to a DNS zone in Cloudflare
  • Default role: choose a default role that will be granted to the new users.

If you want new users who join your team to become a collaborator by default, check “Automatically add new users as collaborators” checkbox.

After the form is filled, click on the “Save” button.

Setup is complete. Now you can logout from the app and log in through the SSO login form.


⚠️ Note: IdP initiated login is not supported.

Users will have to sign-in from Qase’s SSO Login page: https://app.qase.io/sso/login

Did this answer your question?